Senior Analyst – Cyber Threat Intelligence

Brookfield Asset Management

Toronto

On-site

CAD 105,000 - 115,000

Full time

9 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Brookfield Asset Management is seeking a Senior Security Analyst - Cyber Threat Intelligence to monitor, research, and report on emerging threats affecting Brookfield’s people, portfolios, and operations. You will translate external threat activity into actionable insights for security operations and partners across Legal, Privacy, and Fraud teams.

Responsibilities include dark web monitoring, threat actor profiling, and linking IOCs to internal telemetry, with emphasis on MITRE ATT&CK and

Qualifications

  • Experience researching cybercrime activity and dark web or underground ecosystems.
  • Experience conducting OSINT and investigative research using multiple sources and analytical techniques.
  • Strong understanding of threat actor behavior, cybercrime business models, common attack methodologies, and the broader threat landscape.
  • Experience producing intelligence reports and briefings for technical and executive audiences.
  • Experience supporting time-sensitive investigations or incidents and working within defined escalation procedures.

Responsibilities

  • Monitor cyber threats across the dark web, underground forums, marketplaces, messaging platforms, paste sites, and leak sites for Brookfield-related activity.
  • Research and investigate stolen credentials, data leaks, ransomware activity, initial access sales, and fraud schemes.
  • Collect, validate, enrich, and analyze intelligence from OSINT, internal security data, and specialized cybercrime sources; assess credibility.
  • Develop and maintain threat actor profiles covering motivations, capabilities, TTPs, infrastructure, and targeting patterns.
  • Produce concise, actionable intelligence reports, threat assessments, executive briefings, and tactical alerts for security teams.

Skills

Threat intelligence
OSINT research
Dark web monitoring
MITRE ATT&CK
Threat actor profiling
PowerShell/Python
AI-enabled threat knowledge

Education

Post-secondary education in cybersecurity or related field

Tools

PowerShell
Python
OSINT tooling
Threat intelligence platforms
SIEM
EDR/XDR platforms
Dark web monitoring tools

Job description

LocationBrookfield Place - 181 Bay StreetTechnology ServicesTechnology Services (TS) is responsible for delivering all enterprise infrastructure, applications and related end user technology services across all Brookfield business groups.Brookfield CultureBrookfield has a unique and dynamic culture. We seek team members who have a long-term focus and whose values align with our Attributes of a Brookfield Leader: Entrepreneurial, Collaborative and Disciplined. Brookfield is committed to the development of our people through challenging work assignments and exposure to diverse businesses.Job DescriptionThe Senior Security Analyst - Cyber Threat Intelligence is responsible for monitoring, investigating, and assessing emerging cyber threats across the open, deep, and dark web to identify risks that may affect Brookfield, its employees, executives, clients, portfolio companies, technology environment, brand, or critical business operations. This role combines threat intelligence analysis, cybercrime research, dark web monitoring, investigative research, and intelligence reporting to deliver proactive, Brookfield-specific threat visibility. The Senior Analyst works closely with Security Operations, Incident Response, Vulnerability Management, Legal, Privacy, and Fraud teams to translate external threat activity into actionable security and business outcomes.Key ResponsibilitiesMonitor cybercriminal ecosystems across the dark web, underground forums, marketplaces, messaging platforms, paste sites, and leak sites for activity targeting Brookfield, its executives, employees, portfolio companies, brands, domains, and technology environment.Identify and track threat actors, ransomware groups, initial access brokers, malware operators, fraud networks, and criminal collectives relevant to Brookfield's industry, profile, and operations.Research and investigate stolen credentials, compromised accounts, data leaks, ransomware activity, initial access sales, vulnerability exploitation, malware campaigns, phishing operations, business email compromise, and fraud schemes.Collect, validate, enrich, and analyze intelligence from OSINT, commercial intelligence sources, internal security data, and specialized cybercrime sources; assess source credibility and distinguish credible threats from speculation and criminal posturing.Develop and maintain threat actor profiles covering motivations, capabilities, tactics, techniques, and procedures (TTPs), infrastructure, targeting patterns, and historical activity.Correlate dark web intelligence with internal telemetry, security events, threat intelligence feeds, vulnerability information, and publicly available intelligence.Map adversary activity to MITRE ATT&CK and other analytical frameworks; identify indicators of compromise (IOCs), adversary infrastructure, domains, IP addresses, cryptocurrency addresses, and other intelligence artifacts.Produce concise, actionable intelligence reports, threat assessments, executive briefings, and tactical alerts for technical and non-technical audiences.Support Security Operations and Incident Response teams with external threat context during active investigations, ransomware events, data breaches, fraud cases, and third-party compromises.Investigate potential exposure of corporate credentials, sensitive data, intellectual property, customer information, and employee information across underground sources.Validate claims made by threat actors regarding alleged data theft or compromise through appropriate intelligence sources.Monitor and assess the use of artificial intelligence by threat actors, including AI-enabled phishing, business email compromise, executive impersonation, deepfakes, synthetic identities, disinformation, malware development, and automated reconnaissance.Investigate suspected synthetic media and AI-generated content using appropriate technical, contextual, and intelligence-validation methods; communicate confidence levels and analytical limitations clearly.Use approved AI tools to support intelligence collection, translation, analysis, summarization, and reporting while protecting sensitive information and independently validating material conclusions.Develop and maintain repeatable processes for dark web monitoring, threat actor tracking, intelligence collection, source validation, investigative research, and escalation.Maintain intelligence records, threat actor dossiers, watchlists, case notes, and documented evidence in accordance with legal, privacy, and operational-security requirements.Participate in a scheduled information security on-call rotation and provide time-sensitive intelligence support during significant incidents, including ransomware claims, credential exposure, data leaks, executive threats, active exploitation, and third-party compromise.Key DeliverablesContinuous dark web and underground monitoring, with credible threats identified and escalated within defined timelines.Current threat actor profiles for groups relevant to Brookfield's industry and risk profile.Intelligence reports and executive briefings produced on a regular cadence and delivered to security leadership and relevant stakeholders.Credential exposure and data leak investigations completed, with findings documented and remediation actions tracked.IOCs and threat intelligence artifacts delivered to Security Operations and Incident Response teams in support of active investigations.Repeatable intelligence collection and monitoring processes documented and continuously improved.Threat intelligence integrated with internal telemetry to improve detection and response capabilities.Material AI-enabled threats assessed and communicated through timely tactical alerts or executive intelligence reporting.Critical intelligence identified outside regular business hours validated, documented, and escalated within established response targets.Required ExperienceThree to seven years of experience in cyber threat intelligence, cyber investigations, SOC operations, incident response, digital forensics, or security research.Demonstrated experience researching cybercrime activity and dark web or underground ecosystems.Experience conducting OSINT and investigative research using multiple sources and analytical techniques.Strong understanding of threat actor behavior, cybercrime business models, common attack methodologies, and the broader threat landscape.Experience producing intelligence reports and briefings for technical and executive audiences.Experience supporting time-sensitive investigations or incidents and working within defined escalation procedures.Skills & QualificationsStrong analytical and investigative mindset, with the ability to evaluate source credibility and distinguish fact from speculation.Ability to translate complex technical findings into concise, actionable intelligence for technical and non-technical stakeholders.Working knowledge of MITRE ATT&CK, Cyber Kill Chain, Diamond Model, or similar analytical frameworks.Understanding of IOCs, adversary infrastructure, and intelligence artifact analysis.Strong written and verbal communication skills, with experience producing structured intelligence products.Ability to work independently, manage competing priorities, and conduct investigations with appropriate discretion and operational security.Working knowledge of generative AI technologies, AI-enabled threat activity, synthetic media risks, and responsible use of AI-assisted analytical tools.Working knowledge of PowerShell and/or Python is an asset.Preferred QualificationsExperience tracking ransomware groups, initial access brokers, credential theft operations, data extortion groups, malware-as-a-service, or underground marketplaces.Experience with cyber threat intelligence platforms, dark web monitoring tools, SIEM technologies, EDR/XDR platforms, and OSINT tooling.Understanding of cryptocurrency and blockchain activity relevant to cybercrime investigations.Familiarity with threat intelligence standards and formats such as STIX/TAXII.Experience conducting investigations involving credential exposure, ransomware, data extortion, fraud, phishing, business email compromise, or third-party compromise.Familiarity with AI-security risks and recognized guidance such as the NIST AI Risk Management Framework and Generative AI Profile.Relevant certifications such as CTIA, GCTI, GCFA, GCIH, GCIA, CISSP, or Security+.Post-secondary education in cybersecurity, computer science, information security, intelligence studies, criminal justice, or a related discipline, or equivalent practical experience.Additional RequirementThis position participates in a scheduled after-hours on-call rotation and may be required to provide timely support during significant security incidents, critical vulnerabilities, or other urgent security events.Salary Range: C$105K - $115K#LI-MW1Position Opening Reason:New PositionBrookfield is committed to maintaining a Positive Work Environment that is safe, respectful; our shared success depends on it. We do not tolerate workplace discrimination, violence or harassment. We are proud to be an Equal Opportunity Employer and make employment decisions based on qualifications, merit, and business needs, without regard to any characteristic protected by applicable law. Applicant information is collected and handled in accordance with our Applicant Privacy Notice. As part of this commitment, we provide barrier-free and accessible employment practices in accordance with the Accessibility for Ontarians with Disabilities Act (AODA) and applicable human rights legislation. If you require a Human Rights Code-protected accommodation at any stage of the recruitment process, please let us know when contacted, and we will work with you to meet your needs.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Analyst – Cyber Threat Intelligence
Senior Analyst – Cyber Threat Intelligence

Brookfield Asset Management Inc • Toronto

On-site
CAD 105,000 - 115,000
Senior Analyst – Cyber Threat Intelligence
Senior Analyst – Cyber Threat Intelligence

Brookfield • Toronto

On-site
CAD 105,000 - 115,000
Senior Analyst - Security Operations and Assurance
Senior Analyst - Security Operations and Assurance

Brookfield • Toronto

On-site
CAD 105,000 - 115,000
Senior Financial Analyst
Senior Financial Analyst

Brookfield Asset Management Inc • Toronto

On-site
CAD 95,000 - 110,000
Sr. Analyst, Audit, Attestations & Governance
Sr. Analyst, Audit, Attestations & Governance

Brookfield • Toronto

On-site
CAD 80,000 - 100,000
Senior Financial Analyst
Senior Financial Analyst

Brookfield Asset Management Inc. • Toronto

Hybrid
CAD 95,000 - 110,000
Sr. Analyst, Business Systems Analysis
Sr. Analyst, Business Systems Analysis

Brookfield • Toronto

On-site
CAD 95,000 - 115,000
Sr Analyst, DevOps
Sr Analyst, DevOps

Brookfield • Toronto

On-site
CAD 105,000 - 120,000
Manager, Business Systems Analysis
Manager, Business Systems Analysis

Brookfield Asset Management Inc • Toronto

On-site
CAD 115,000 - 130,000
Sr Analyst, DevOps
Sr Analyst, DevOps

Brookfield Asset Management • Toronto

On-site
CAD 105,000 - 120,000